Phantom Squatting: When Attackers Camp on the Domains LLMs Hallucinate

Unit 42 documents a pre-positioning tactic where actors register non-existent domains that AI assistants keep suggesting, then wait for the traffic to arrive.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 3 min read
Illustration: a dark server rack aisle with faint blue and violet indicator lights, wisps of fog drifting between cabinets
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Unit 42 has named the abuse pattern "phantom squatting": attackers register domains that LLMs hallucinate, then host phishing or malware pages there.
  • Victims arriving via an AI assistant's recommendation are primed to trust the destination, lifting the success rate above generic phishing lures.
  • Attribution remains thin; the low barrier to entry points to a broad mix of actors rather than a single tracked cluster.
  • The web-domain pattern mirrors "slopsquatting," where malicious packages are registered under hallucinated names on package registries.
  • Newly registered domain filtering and treating AI-suggested URLs as untrusted input are the most actionable near-term defences.

What is phantom squatting?

Large language models make things up. Sometimes those things are URLs. Unit 42's research, published by Palo Alto Networks, shows attackers registering the non-existent domains that AI assistants confidently recommend, then hosting credential-harvesting or drive-by malware pages there to catch traffic the models point their way. When the next user follows the same AI suggestion, they land on infrastructure the adversary controls. It's typosquatting with a new upstream: instead of banking on human misspellings, the operator bets on model output.

Our earlier look at bucket squatting inside Google's Vertex AI SDK on 17 June showed the same pre-registration logic applied to cloud storage paths. The mechanics transfer cleanly to web domains.

Why does this work so well?

Traffic quality is the core appeal. A victim who arrives because an AI assistant recommended the page is already inclined to trust it, which pulls click-through rates on credential harvesting above what generic phishing lures produce. Phantom squats also blend into existing domain-abuse noise: bulk registration, cheap TLDs, fast-flux hosting. Detection is harder precisely because the TTPs overlap so heavily with commodity infrastructure.

How does this connect to slopsquatting?

Coding assistants hallucinate package names on npm and PyPI. Researchers have warned about "slopsquatting," malicious packages registered under those invented names, for over a year. Phantom squatting is the web-domain cousin of that failure mode: same root cause, different payload surface. On the developer side, lockfiles and verified internal package mirrors blunt the package-registry variant.

Should you worry about attribution?

Attribution here is thin. No public reporting has tied phantom squatting to a specific tracked cluster, and the technique's low barrier to entry means it's plausible across commodity phishers and initial access brokers alike, with state-aligned collection crews a lower-confidence possibility. Assess with low confidence that any single group owns the tradecraft.

What can defenders do?

For enterprise environments, treat AI-assistant output as untrusted input. Route chatbot-suggested URLs through the same secure web gateway inspection applied to email links. Newly registered domain filtering catches a meaningful slice of this activity because phantom squats are, by definition, freshly acquired.

The deeper problem is structural. LLM providers have limited incentive to fix hallucination at the URL layer, and no clean way to do it without breaking legitimate outputs. Adding a live existence check helps at the margin, but attackers can pre-register faster than models retrain.

Detection engineers should start pulling AI-referrer telemetry from their proxies now, if that data is available. That's where the signal will live, and it isn't being collected widely yet. This one's being undersold as opportunistic: the trust premium that AI referrals carry makes phantom squatting a better conversion tool than most phishing setups defenders are already tracking.

© 2026 Threat Vectr